ZenStack Language Tools
The AI review rates the findings as likely false positive, but the risk score (73/100) still counts them.
Analysis record
- Analysed
- 3 days ago
- Version
- v2.20.0
- Artifact
- SHA256 26B…A29
- Source
- Findings (non-IoC)
Evidence ledger
Ranked by severity · findings with a source location link to the code viewer
YARA Rule Matches
1 rule| Severity | Rule | Hits | Files | Metadata |
|---|---|---|---|---|
| HIGH | supply chain sourcemap appended iife | 1 | zenstack/language-server/main.js | - |
Publisher Evidence
Limited evidenceZenStack
Publisher identity, store signals, distribution reach, and warning signals used for context. Treat this as supporting evidence, not a clean bill of health.
13 evidence rows available.
Finding Categories
YARA Rules Matched
1 ruleAI Security Report
AI Security Review
Evidence context: threat category none; evidence quality strong.
ZenStack Language Tools is a JetBrains IDE extension that provides language server support and syntax highlighting for ZenStack, a data modeling and ORM framework. The extension's filesystem and process access is fully justified by its stated purpose as a language tool. The extension contains legitimate development files including zenstack/language-server/main.js for language server functionality, zenstack/res/zmodel.tmbundle/Syntaxes/zmodel.tmLanguage for syntax highlighting, and bundled JAR files like zenstack/lib/searchableOptions-2.20.0.jar and zenstack/lib/instrumented-zenstack-2.20.0.jar for runtime libraries.
There are no credential-access findings targeting actual secrets. The findings summary shows zero detections in the "secret" category, meaning no code was flagged for reading .env files, SSH keys, cloud credentials, or VS Code secret storage. The extension's metadata findings consist entirely of file integrity hashes for its own bundled resources, which is standard practice for extension integrity verification and poses no security risk.
The strongest counterargument to this verdict would be that any extension with language server capabilities inherently has broad filesystem access and could theoretically exfiltrate code. However, this argument does not apply here because the findings show zero network activity flags, zero data exfiltration patterns, and zero malware signatures. The threat_indicators summary explicitly shows "ioc":"0","malware-signature":"0","malware":"0","network":"0", confirming no suspicious behavior was detected. Additionally, the extension has 3,599 users on JetBrains Marketplace, indicating it is actively maintained and widely trusted in the developer community.
All six findings in the bundle are "info" severity metadata entries containing SHA hashes of the extension's own files. These are not security findings but rather integrity tracking records. There are no code-smell detections, no obfuscation flags, no dependency vulnerabilities, and no manifest analysis warnings. This pattern is consistent with a legitimate, well-maintained language tool extension that has been properly analyzed and found to contain no security concerns.
Key Reasons
- Zero malware signatures or IoC matches detected
- All findings are benign file integrity hashes with info severity
- Extension serves legitimate language tool purpose with justified access patterns
- No credential access or network exfiltration findings
False Positive Considerations
- metadata file hashes misclassified as findings
- zero actual security detections in all threat categories
- benign language server extension with standard bundled libraries
Reviewed 2026-05-24; recommended action: no action; model confidence 95%.
About This Extension
Frequently Asked Questions
Similar Extensions
Related extensions from the same publisher or marketplace